Learning objectives
- Configure Microsoft Defender XDR capabilities
- Collect and analyse data in Microsoft Sentinel
- Create detections and conduct investigations with KQL
- Respond to incidents and conduct threat-hunting activities
Who should attend
SOC analysts, security engineers and professionals responsible for detection and response.
Prerequisites
Knowledge of security, Azure, Microsoft 365, systems and networking. Basic KQL knowledge is recommended.
Course outline
- Microsoft Defender XDR and protection of identities, endpoints and applications
- Microsoft Defender for Cloud and security posture
- Microsoft Sentinel architecture, connectors and workspaces
- KQL for analysis, detections and reporting
- Incidents, automation, playbooks and response
- Threat hunting, advanced investigation and SC-200 preparation
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: Microsoft Learn, SC-200T00-A ↗
Programme structured around the skills objectives published on Microsoft Learn and delivered by a Microsoft Certified Trainer.
Programme structured around the skills objectives published on Microsoft Learn and delivered by a Microsoft Certified Trainer.
